Host Header Routing Bypass in http4k by 36g
CVE-2026-100724

6.3MEDIUM

Key Information:

Vendor

Http4k

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100724?

The http4k library contains a vulnerability where functions responsible for routing requests to virtual hosts can be exploited. When configured with two or more virtual hosts, an attacker can manipulate the Host header in HTTP requests, causing the server to incorrectly route to a different virtual host. This bypasses the intended authorization checks, allowing unauthorized access to potentially sensitive resources on the targeted application. It's crucial for users running affected versions to upgrade to the latest releases to mitigate these risks.

Affected Version(s)

http4k 0 < 6.49.0.0

http4k 0 < 5.42.0.0

http4k 0 < 4.51.0.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.